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(54) Microprocessor and debug system 

(57) A microprocessor (10) has a processor core 
(20) and a debug module (30). The processor core (20) 
executes a user program and a monitor program for 
debugging a user target system (70). The debug module 
(30) serves as an interface with a debug tool (60), to let 
the processor core (20) execute the monitor program 



stored in the debug tool (60). The debug module (30) 
makes an interrupt or exception request to switch the 
processor core (20) from the user program to the monitor 
program. 
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Description 

BACKGROUND OF THE INVENTION 

5 1, Ftelfl Of the Invention 

The present invention relates to a microprocessor and debug system having a function of tracing a program counter 
and a function of notifying outside that a preset address or data has been accessed. 

w 2. Description of the Prior Art 

Figure 1 shows a debug system called an in-clrcuit emulator according to a prior art. 

The system includes a user target system 500 and a debugger 505 for debugging the target system 500. The target 
system 500 has a microprocessor 501 , a memory 503, and an I/O unit 502. The debugger 505 has a debugging micro- 
's processor 506 and a monitor program memory 507. 

To debug the target system 500, the microprocessor 501 is removed or disabled, and probes of the debugger 505 
are connected to the place of the microprocessor 501 so that the microprocessor 506 may operate instead of the micro- 
processor 50 1 . The microprocessor 506 executes a monitor program stored in the memory 507, to control a user program 
stored In the memory 503. 

to The microprocessor 506 executes the user program, accesses data in the memory 503, and accesses the I/O unit 
502. The debugger 505 has a trace memory 508. so that the microprocessor 506 may provide trace information about 
an internal slate such as the value of a program counter that is usually not provided by the microprocessor 501 through 
a processor bus 504. 

The prior art of Fig. 1 , however, must connect the debugger 505 to all pins of the microprocessor 501 of the target 
25 system 500. The microprocessor 501 has, for example, 70 pin6 for 30 address signals, four byte-enable signals, a read 
signal, a write signal, a read acknowledge signal, a write acknowledge signal, and 32 data signals. The debugger 505 
must have probes for these pins, and therefore, is expensive and unstable. The microprocessor 506 must switch buses 
from one to another to access the memory 503 of the target system 500 and the memory 507 of the debugger 505, and 
therefore, is not applicable to a high-speed microprocessor. 
30 If the target microprocessor has peripheral elements, it may have a different pin arrangement In this case, the 
debugger must have probes proper for such a pin arrangement When connected to the target system 500, the probes 
of the debugger 505 may influence and destabilize signals in the target system 500. 
Figure 2 6hows a debug system called a ROM monitor according to another prior art. 

A U6er target system 510 has a serial interface 512 connected to a host computer 517. A memory 513 stores a 
35 monitor program 514. A microprocessor 51 1 executes the monitor program 514 to access the memory 513. an I/O unit 
515, and a register 516. A software break instruction is used to execute and control a user program. 

This prior art employs the user memory 51 3 to store the monitor program 51 4. if the memory system of the target 
system 51 0 is imperfect, the monitor program 51 4 itself will be unstable. If the capacity of the memory 51 3 is small, there 
will be no space to store the monitor program 514. Since a monitor mode is started by a user interrupt some program 
<o may not be debugged. The serial interface 512 mounted on the target 6ystem 510 is imperative for debugging but i6 
useless after debugging. The debugging performance of this prior art is poor because it has no hardware break point 
and because it is incapable of tracing a program counter. 

Figure 3 shows a debug system according to still another prior art. 

A user target system 520 has a microprocessor 521, which incorporates a serial interface 526 and a sequencer 
45 525. The serial interface 526 communicates with a debug tool 529. The debug tool 529 sends signals to the interface 
526, and the sequencer 525 interprets the signals. Jn response to the signals, the sequencer 525 temporarily stops ihe 
execution of a user program, accesses a register 528. uses a bus controller 527 to access an I/O unit 523 and a memory 
524, and controls the user program. The serial interface 526 is usually incapable of directly communicating with a host 
computer 530. Accordingly, the debug tool 529 converts a command from the host computer 530 into a signal under- 
so standabie by the microprocessor 521 , and a signal from the microprocessor 521 Into a data format understandable by 
the host computer 530. 

The microprocessor 521 incorporates the sequencer 525, which must access the microprocessor 521 as well as 
the debug tool 529. In this way, this prior art employs a complicated connection logic to increase a chip area. If the target 
system 520 is provided with an additional register, the sequencer 525 must be modified accordingly through a compli- 
ss cated work. This prior art is incapable of tracing a program counter. 

As explained above, the prior arts are incapable of tracing a program counter, or even if they can, they must connect 
many signals between a debug processor and a target system through a processor bus. According to the prior art of 
Fig. l . tfie microprocessor 506 of the debugger 505 must access the memory 503 and I/O unit 502 of the target system 
500, and it is difficult to cortlrol the timing of these access operations. 
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The prior art of Fig. 2 stores a monitor program in the user memory 51 3. to reduce a user memory space. Debugging 
by this prior is unsure and insufficient 

The prior art of Fig. 3 incorporates the sequencer 525 in the microprocessor 52 1 of the target system 520. to interpret 
and execute signals sent from the debug tool 529. Namely, this prior art Involves a complicated connection between a 
s target system and a debug tool. If II is required to modify the microprocessor 521 , the sequencer 525 must al60 be 
modified through a complicated work. 

The prior arts of Figs. 2 and 3 have no trigger function. The prior art of Fig. 1 may have the trigger function in the 
debugging microprocessor 506 but with additional signals for providing trigger information. 

10 SUMMARY OF THE INVENTION! 

An object of the present invention is to provide a microprocessor disposed in a user target system, tor achieving a 
debugging function with a small number of signals between the target system and a debugger. 

Another object ol the present invention is to provide a microprocessor disposed in a user target system, for achieving 
15 a debugging function with the microprocessor operating on the target system to easily access memories and I/O units 
of the target system. 

Still another object of the present invention is to provide a microprocessor disposed in a user target system, for 
achieving a debugging function to trace a program counter with a 6mall number of signals. 

Still another object of the present invention Is to provide a microprocessor disposed in a user target system, lor 
so achieving a debugging function with minimum hardware by sharing address and data comparators with a hardware 
break function and trigger function and by sharing output signals with program counter information and trigger informa- 
tion. 

In order to accomplish the objects, a first aspect of the present Invention provides a microprocessor having a proc- 
essor core and a debug module. The processor core executes a user program as well as a monitor program for debugging 

25 a user target system. The debug module is connected to the processor core through an internal debug interface and a 
processor bus. The debug module has an interface that enables the processor core to execute a monitor program stored 
in a debug tool. The debug module also has an execution controller for making an interrupt or exception request to the 
processor core for switching the processor core from the user program to the monitor program. 

A second aspect of the present invention provides a debug system. In the system, a debug tod stores a monitor 

30 program for debugging a user target system. The target system includes a microprocessor, a memory, and an I/O unit. 
The microprocessor has a processor core and a debug module. The processor core executes a user program or the 
monitor program. The debug module is connected to the processor core through an internal debug interface and a 
processor bus. and to the debug tool through an external debug interface. The interfaces of the debug module enable 
the processor core to execute the monitor program. The debug module also has an execution controller tor making an 

55 interrupt or exception request to the processor core for switching the processor core from the user program to the monitor 
program. The memory is connected to the microprocessor through the processor bus and stores information necessary 
for the microprocessor to execute the user program The I/O unit is connected to the microprocessor through the proc- 
essor bus. 

According to the first and second aspects, the microprocessor of the target system has the debugging function, to 
40 reduce the number of signals between the target system and the debug tool. The first and second aspects operate the 
microprocessor during debugging, to easily access the memory and I/O unit of the target system. 

A third aspect of the present invention provides a microprocessor having a processor core for executing a program 
and a tracer for tracing a program counter. The tracer is connected to the processor core through an internal debug 
interface and provides a program counter signal representing the address of an instruction to be executed by the proe- 
ms essor core. The number of signal lines for transmitting the output signal is smaller than the number of bits of the instruction 
address. 

According to the third aspect, the microprocessor of the target system has the debugging function, to reduce the 
number of interface signals used for tracing the program counter. 

A fourth aspect of the present invention provides a microprocessor having a processor core for executing programs, 
so a break circuit, and a program counter tracer. The break circuit provides the processor core with a break request or a 
trigger request when an accessed address coincides with a set address or when an accessed address and data coincide 
with set address and data. The tracer provides an external status signal informing that the trigger request has been 
enabled. 

According to the fourth aspect, the microprocessor of the target system has the debugging function, an address 
ss comparator is shared by the hardware breakfunction and trigger function, and the output of the tracer is used to provide 
trigger information, to minimize hardware. 
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BRIEF DESCRIPTION OF THE DRAWINGS 

These and other objects, features, and advantages of the present invention will be more apparent from the following 
descnpbon of preferred embodiments taken in conjunction with the accompanying drawings in which: 

Fig. 1 shows a debug system for debugging a user target system according to a prior art: 

Fig, 2 shews a debug system tor debugging a user target system according to another prior art; 

Fig. 3 shows a debug system for debugging a user target system aocording to still another prior art; 

Ftg. 4 shows a debug system and a microprocessor accoitiing to an embodiment of the present invention; 
10 Fig. 5 shows a debug module of the embodiment of Fig. 4; 

Fig. 6 shows a register circuit of the embodiment of Fig, 4; 

Fig. 7 shows a debug control register (OCR) of the register circuit of Fig. 6; 

Fig. 8 show6 an instruction break address 0 (I BAG) register of the register circuit of Fig. 6; 

Fig. 9 shows an instruction break control 0 (IBCO) register of the register circuit of Pig. 6; ' 
is rig. 1 0 shows an instruction break status (IBS) register of the register circuit of Fig. 6; 

Fig, 1 1 shows a data break address 0 (DBAO) register of the register circuit of Fig. 6; 

Fig, 12 shows a data break control 0 (DBCO) register of the register circuit of Fig. 6; 

Fig. 1 3 shows a data break status (DBS) register of the register circuit of Fig. 6; 

Fig. 14 shows a processor bus break address 0 (PBAO) register of the register circuit of Fig. 6; 
20 Fig. 1 5 shows a processor bus break data 0 (PBDO) register of the register circuit of Fig. 6: 

Fig. 16 shows a processor bus mask 0 (PBMO) register of the register circuit of Fig. 6; 

Fig. 1 7 shows a processor bus control 0 (PBCO) register of the register circuit of Fig. 6; 

Fig. 18 shows a processor bus break status (PBS) register of the register circuit or Fig. 6; 

Fig. 1 9 shows an instruction/data address break circuit of the debug module of Fig. 5; 
25 Fig. 20 shows a processor bus break circuit of the debug module of Bg. 5; 

Fig. 21 shows a serial monitor bus circuit of the debug module of Fig. 5; 

Fig. 22 is a timing chart showing a read operation of the serial monitor bus circuit; 

Fig. 23 is a timing chart showing a write operation of the serial monitor bus circuit; 

Fig. 24 Is a timing chart showing a read operation of the serial monitor bus circuit according to an Instruction CFCO; 
so Fig. 25 is a timing chart showing a write operation of the serial monitor bus circuit according to an instruction CTCO; 

Fig, 26 is a flowchart showing the operation of the serial monitor bus circuit of Fig. 21 ; 

Fig. 27 is a flow chart showing a read operation of the serial monitor bus circuit; 

Fig. 28 is a flowchart showing a write operation of the serial monitor bus circuit; 

Fig. 29 shows a program counter tracer of the debug module of Fig. 5; 
35 Fig. 30 is a timing chart showing a program counter output according to a branch instruction; 

Fig. 31 is a timing chart showing a program counter output according to an indirect jump instruction; 

Fig. 32 is a timing chart showing a program counter output according to an exception and an indirect jump instruction; 

Fig. 33 is a timing chart showing an instruction/data address trace trigger; 

Fig. 34 is a timing chart showing an instruction/data address trace trigger generated in response to an exception 
«> generating instruction; 

Fig. 35 is a timing chart showing an instruction/data address trace trigger generated in response to an indirect 
instruction; 

Fig. 3S is a timing chart showing an output signal PCS*TJ2:0] when a debug exception occurs; 
Fig. 37 is a timing chart showing the signal PCSTI2:01 when a debug exception occurs while the output of a target 
45 program counter is being provided; 

Fig. 38 is a timing chart showing the 6ignal PCST[2;0] when a normal mode Ig restored after a debug mode; 
Fig. 39 is a timing chart showing the output of a target program counter; 

Fig. 40 is a timing chart showing the next indirect jump occurred while the output of a target program counter is 
being provided; 

so Fig. 41 is a timing chart showing an exception occurredwNle the output ofa target program counter i6 being provided; 
Fig. 42 show6 an external interface circuit of the debug module of Fig. 5; 
Fig. 4$ shows an expanded IBS register; and 

Fig. 44 shows a debug system according to an embodiment of the present invention. 
55 DETAILED DESCRIPTION OF THE EMBODIMENTS 

Figure 4 shows a debug system and a microprocessor according to an embodiment of the present invention. 
The debug system has a user target system 70 and a debugger 60. 
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The target system 70 has the microprocessor 10. a memory 40, and an I/O unil 50. The microprocessor 10 has a 
debugging function. 

The microprocessor 10 has a processor core 20 and a debug module 30. The processor core 20 accesses the 
memory 40 and I/O unit 50 through a processor bus 80 and executes a program. The processor core 20 is connected 
s to the debug module 30 through an internal debug interlace and the processor bus 80. The debug module 30 is connected 
to the debugger 60 through an external debug interface. 

The debug system takes a debug mode to execute a monitor program and a normal mode to execute a user program. 

(Debug mode) 



The processor core 20 generates a debug exception or a debug reset to start the debug mode. The processor core 
20 jumps to a debug exception vector address FF20 J5200 or a debug reset vector address FF20 0000 and asserts a 
debug mode signal DM. A memory accessed with these vector addresses is in the debugger 60~The processor core 
20 executes the monitor program stored in the debugger 60 through the debug module 30. The monitor program executes 
and controls the user program by reading and writing memories and registers and by specifying start and end addresses 
of the user program. The processor core 20 may execute a return instruction to return to the normal mode and execute 
the user program. In this case, the processor core 20 jumps to an address specified by the return instruction and negates 
the debug mode signal DM. 



20 (Normal mode) 



Under the norma] mode, the debug system executes the user program, and at the same time, traces a program 
counter. The debug system may switch the normal mode to the debug mode by generating a debug exception or a debug 
reset tor the processor core 20 through a hardware break, software break, or debug interrupt. 
26 The program counter trace function, hardware break function, software break function, debug interrupt function, 
debug reset function, and trace trigger function that are enabled under the normal mode will be explained. 

The program counter trace function traces a value in the program counter while the processor core 20 is executing 
the user program stored in the memory 40. While the processor core 20 is executing the user program, the program 
counter information is sent to the Internal debug interface. The debug module 30 processes the information and sends 
30 the processed information to the debugger 60 through the external debug interface- 

The hardware break function produces a debug exception when an instruction having a predetermined address is 
executed, or when data at a predetermined address is accessed, to let the processor core 20 execute the monitor 
program. More precisely, the debug module 30 compares the address of an instruction to be executed by the processor 
core 20 with an instruction address stored in the debug module 30, or the address of data to be accessed by the processor 
35 core 20 with a data address stored in the debug module 30, or data provided by the processor core 20 with data stored 
in the debug module 30, and if they coincide with each other, provides the processor core 20 with a debug exception 
request or a debug interrupt request. 

The software break function produces a software break instruction to generate a debug exception, to let the proc- 
essor core 20 execute the monitor program. 
40 The debug interrupt function asserts a debug interrupt signal to produce a debug exception, to let the processor 
core 20 execute the monitor program. 

The debug reset function asserts a debug reset signal to cause a debug reset, to initialize the internal states of the 
processor core 20 and debug module 30- Then, the processor core 20 is put in the debug mode to start the debug 
program from the debug reset vector address FF20_ 0000. 
45 The trace trigger function lets the microprocessor 10 send an external signal indicating that an instruction having a 
predetermined address is executed, or that data at a predetermined address is accessed. In response to the signal, the 
debugger 60 turns ON/OFF the program counter trace function. This function is carried out to provide the debugger 60 
with trigger information after the debug rnoduie 30 compares the address of an instruction to be executed by the processor 
core 20 with the instruction address stored in the debug module 30, or the address of data to be accessed by the 
bo processor core 20 with the data address stored in the debug module 30, or data sent from the processor core 20 to the 
internal debug interface and processor bus 80 with the data stored in the debug module 30, and if they coincide with 
each other. 

The details of the debug module 30 will be explained. 

Figure 5 shows Internal blocks of the debug module 30. 
55 The debug module 30 has an instruction/data address break circuit 31, a program counter tracer 32, a processor 
bus break circuit 33, a serial monitor bus circuit 34, a register circuit 35, an external interface circuit 36, and a clock 
generator 37. 

The instruction/data address break circuit 31 is connected to the processor core 20 through the internal debug 
interface. The circuit 31 compares an instruction address provided by the processor core 20 with an instruction address 
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Bet in the register circuit 35, and if they coincide with each other, provides the processor core 20 with an instruction 
address break exception request. The circuit 31 also compares a data address provided by the processor core 20 with 
a data address sel in the register circuit 35, and if they ooincide with each other, provides the processor core 20 with a 
data address break exception request 

& The program counter tracer 32 Is connected to the processor core 20 through the internal debug interface, to process 
program counter trace information provided by the processor core 20 and provide the external interlace circuit 36 with 
the processed information. 

The processor bus break circuit 33 is connected to the processor core 20 through the processor bus 80. The circuit 
33 monitors bus cycles in the processor bus 80, and when a bus cycle for the address and data set in the register circuit 
10 35 is carried out, provides the processor core 20 with an exception request 

The serial monitor bus circuit 34 is connected to the processor core 20 through the processor bus 80 and serves 
as an interface when the processor core 20 executes the monitor program of the debugger 60. 

The register circuit 35 includes control registers to control the functions of the debug module 30- The register circuit 
35 is connected to the processor core 20 through the processor bus 80 and internal debug interlace, so that the processor 
is core 20 may read and write the contents of the control registers. The contents of the control registers are supplied to 
the elements of the debug module 30 and the processor core 20. to control the debug functions. 

The external inlerface circuit 36 interfaces the program counter tracer 32 and serial monitor bus circuit 34 of the 
debug module 30 and the processor core 20 with the debugger 60. 

The clock generator 37 divides the frequency of a dock signal CLK and provides the serial monitor bus circuit 34 
20 with a clock signal CLK2. 

(External signals) 

The debug module 30 employs the following eight dedicated interface signals to communicate with the external 
ss debugger 60; 

1 . SDAO/TPC (output) 

2. SDI/DINT* (input) 

3. D CLK (output) 
30 4. D RESET- (input) 

5 to 7, PCST[2:0] (output) 
8. DBGE* (input) 

(1) Debug dock signal DCLK (output) 

35 

This signal is an output clock signal to the debugger 60, to control the timing of signals in a serial monitor bus and 
program counter trace interface. For the operation of the serial monitor bus, this 6ignal is formed by halving the frequency 
of an operation clock signal of the processor core 20. 

40 (2) Debug reset signal DRESET* (input to pull-up terminal) 

This signal is a low-active signal and is asserted to initialize the debug module 30 without regard to the input signal 
OBGE*. A terminal for this signal i6 disconnected when the debugger 60 is not used. 

45 (3) Program counter trace status signal PC$T[2:0] (output) 

This signal represents the following program counter tracing states and a serial monitor bus mode: 
ill: pipeline stall state (STL) 

1 10; branch/jump taken state (JMP) (with program counter output) 
so 101; branch/jump taken state (BRT) (without program counter output) 

100: exception state (EXP) (with exception vector code output) 

011: sequential execution state (SEQ) (instruction execution) 

010: trace trigger output state (TST) in pipeline stall 

001 : trace trigger output state (TSQ) in execution 
55 000: debug mode (DBM) (0: low level, 1 : high level) 
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(4) Debugger enable signal DBGE* (input to pull-up terminal) 

This signal indicates whether or not the debugger 60 is connected. If the debugger 60 is not connected, ihe signal 
is high, and if it is connected, the signal Is low. 
g If the signal DBGE" is high to indicate that the debugger 60 is not connected, a signal DEV ol the processor core 
20 is low, and a debug exception vector address is FF200200. A user reset signal RESET* initializes the functions ol 
the debug module 30 and disables the lunetions of the debugger 60. At this time, the output signals SDAO/TPC, DCLK, 
and PCST12:0] become high. 

if the signal DBGE* is low to indicate that the debugger 60 is connected, the signal DEV is high, and a debug 
10 exception vector address is FF20_0200 (in a monitor area), The user reset signal RESET* does not initialize the debug 
module 30. 

(5) Serial data and address output/target program counter signal SDAO/TPC (output) 

is This signal serves as a serial data and address output signal SDAO when the signal PCST[2:0] indicates the debug 
mode (DBM), and as a target program counter signal TPC when the signal PCST[2:0]does not indicate the debug mode. 

When the signal PCST[2:0] indicates the debug mode, the signal SDAO provides data, address, read/write, and 
byte-enable signals bit by bit in series. Before starting a bus cycle, a low-level start bit signal is provided for a clockperiod. 

In a read operation, the signals are provided in order of the low-level start bit, address bits A[2] to A[19], read/write 
20 bit R/W. and byte-enable bits BE[0]* to BE(3]\ in a write operation, the signals are provided in order of the low-level 
start bit, A[2] to A[19], R/W\ BE[0]* to BE[3]\ and data bits D[0] to Dpi]. 

When the signal PCST[2:0] indicates the normal mode, the signal TPC provides the target address of a branch/jump 
instruction and the vector number of an exception/interrupt. The target address i6 sequentially provided from a bit A[2] 
to a bit A[31]. 

25 

(6) Serial data input/debug interrupt signal SDI/DINT* (input to pull-up terminal) 

This signal serves as a serial monitor bus interface signal SD1 when the signal PCST[2:0] indicates the debug mode, 
and as a program counter trace interface signal DINT* when the signal PCST[2:0] indicates the normal mode. 
w The signal SD I is a data input signal. When an external 6tart bit, which is low for a clock period, is received in a read 
operation, a data input operation starts from the next clock. When there is a low-level input in a write operation, the bus 
cycle ends. 

in a read operation, bits are provided in order of a low-level start bit and data bits D[0] to D[31]. In a write operation, 
only a low-level end bit is received. 
as The signal DINT" is a debug interrupt input signal from the debugger 60. When the debugger 60 is not used, the 
terminal is disconnected. 

Figure 6 shows the details of the register circuit 35. 

The register circuit 35 consists of an address decoder 351 and a register unit 352. 

The address decoder 351 receives, from the processor core 20 through the processor bus 80, an address input 
*o signal A[31 :0], read signal RD*. write signal WR*. debug mode signal DM. and core clock signal CLK. When reading a 
register in the register unit 352, the address decoder 351 receives an address indicating the register, decodes the 
address, asserts a register read signal corresponding to the register, and asserts a read acknowledge signal RDACK* 
to the processor core 20. 

When writing data to a register in the register unit 352 corresponding to a given address, the address decoder 351 
46 asserts a register write signal corresponding to the register, the read acknowledge signal RDACK*, and a write acknowl- 
edge signal WRACK*. 

The register unit 352 is inaccessible under the normal mode. In this case, the address decoder 351 only asserts 
the read acknowledge signal RDACK* to the processor core 20 in a read bus cycle and the write acknowledge signal 
WRACK* to the processor core 20 in a write bus cycle. As a resutt a value to be read is undefined, and write data is 
so ignored. 

Even under the debug mode, the registers of the register unit 352 except the register DCR are inaccessible (f a 
memory protection bit MP of the register DCR is set In this case, the address decoder 351 only asserts the read acknowl- 
edge signal RDACK* in a read bus cycle and the write actonowledge signal WRACK" in a write bus cycla As a result, a 
value to be read is undefined, and write data is ignored- 

ss 
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Table 1 shows the operation of the address decoder 351 . 



Table 1 



Accessed 
register 


Address 
A[31:2] 


Read 
RD« 


Write 
WR* 


DM 


MP 


Read 
ack. 
RDACK* 


write 
ack. 
WRACK* 


Asser ted 
signal 


DCR 


FF300000 


Low 


High 


High 




Low 
High 


High 
Low 


DCR Read 
DCR Write 


High 


Low 




X 


IBS 


FF300004 


Low 


HigV 


High 


0 


Low 
High 


High 
Low 


IBS Read 
IBS Write 


High 


Low 




DBS 


FF3OOO0S 


Low 


High 


High 


0 


Low 
High 


Hi gh 
Low 


DBS Read 
DBS Write 


High 


Low 




PBS 


FF30000C 


Low 


Hijgh 


High 


0 


Low 
High 


High 
Low 


PBS Read 
PBS Write 


High 


Low 




ISAO 


FF300010 


Low 


Hifch 


High 


0 


Low 
High 


High 
Low 


IBAO Read 
IBAO Write 


High 


Low 




IBCO 


FF300014 


Low 


Hifch 


High 


0 


Low 
High 


High 
Low 


IBCO Read 
IBCO Write 


High 


Lbw 




DBAO 


FF300020 


Low 


Hiffi 


High 


0 


Low 
High 


High 
Low 
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The register unit 352 includes a debug control register (DCR), instruction break status (IBS) register, data break 
status (DBS) register, processor bus break status (PBS) register, instruction break address 0 (IBAO) register, instruction 
break control 0 (IBCO) register, data break address 0 (DBAO) register, data break control 0 (DBCO) register, processor 
bus break address 0 (PBAO) register, processor bus break data 0 (PBDO) register, processor bus break data mask 0 
55 (PBMO) register, and processor bus break control 0 (PSCO) register. 

The registers are reset whan the debug reset signal DRESET* is asserted, or when the user reset signal RESET* 
is activated with the signal DBGE" being high to indicate that the debugger 60 is disconnected. 

The functions of the registers will be explained. 

Figure 7 shows the debug control register (DCR). 



8 



FEB. 28. 2006 2:51PM ARENT FOX DC5 



MO. 7249 P. 20 



EPO 720 093 A1 

Trace mode bit TM (reset to 0) 

This bit specifies a program counter trace operation. 
O: provide program counter trace information in real time 
s i : provide complete program counter trace information (without assuring a real-time operation) 

The bit TM is supplied to the program counter tracer 32. 

Mask user reset bit MRst (reset to O) 

10 This bit specifies a user reset mask. 

O: mask UBer reset fn debug exception 

1 : enable user reset in debug exception 

The bit MRst is supplied to the external interface circuit 36. 

75 Memory protection bit MP (reset to 1) 

0: enable write operation to monitor area under the debug mode 

1 : protect monitor area (FF20_0000 to FF3F_FFFF) except the register DCR against write operation under the 
debug mode 

20 The bit MP is supplied to the address decoder 351 and serial monitor bus circuit 34. 

Mask non-mask interrupt bit MNml (reset to 1) 

0: mask Nml of the processor core 20 
2s 1 : enable Nml 

The bit MNml is supplied to the processor core 20- 

Mask interrupt bit Mint (reset to 1} 

so 0: mask external Interrupt (1nt[5:0]*) of the processor core 20 

1: enable external interrupt (lnt[5;0]*) 
The bit Mint is supplied to the external interface circuit 36. 



36 



SO 



Endian memory bit ENM 



This bit indicates the value of an endian signal when a user reset operation is carried out. This bit is readonly, and 
a write operation to the bit is ignored. 
0: little endian 
1 : big endian 

40 The bh ENM is formed by latching the endian signal at a rise of the core dock signal with the user reset signal 

RESET' being low. 

Halt status bit HIS 

4S This bit indicates the value of a halt 6ignaJ when the signal DINT* is active. The bit HIS is read-only, and a write 
operation to this bit is ignored. 
0: not halt state 
1: halt state 

The bit HIS is formed by latching the halt signal at a rise edge of the debug interrupt signal dint*, 



Doze status bit DzS 



This bit indicates the value of a doze signal when the signal DINT" Is active. The bit D*S l6 read-only, and a write 
operation to this bit is ignored. 
ss 0: not doze state 

1 : doze state 

The bit DzS is formed by latching the doze 6lgnal at a fall edge of the debug interrupt signal DINT*. 
Figure 8 shows the instruction break address 0 register IBA0« 
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Instruction break address field IBA 

This field of the register IBAO stores an instruction break address, which is a virtual address. The field IBA is supplied 
to the Instruction/data address break circuit 31 . 
6 Figure 9 shows the instruction break control 0 register IBCO. 

Break enable bit BE (reset to 0) 

This bit specifies the validity of the instruction address break function. 
10 0: disable the instruction address break function 

1 : enable the instruction address break function 

If the virtual address of an instruction to be executed coincides with an address set in the register IBAO with the 
bit BE being 1 , an instruction break request is made to the processor core 20, to set a bit BS0 of the register IBS. (The 
processor core 20 generates an Instruction address break exception just before executing the instruction whose address 
15 has made the coincidence.) The bit BE is supplied to the break circuit 31 . 

Trace trigger enable bit TE (reset to 0) 

This bit specifies the validity ol the instruction address trace trigger function. 
20 0: disable the instruction address trace trigger function 

1 : enable the instruction address trace trigger function 

If the virtual address of an instruction executed coincides with an address set in the register IBAO with the bit TE 
being 1 to indicate the enabled instruction address trace trigger function, the signal PCST[2:0] represents the trace 
trigger output state TST(0 1 0) or TSQ(O0 1 ), to 6el a bit BSO of the register I B6. The bit TE is supplied to the break circuit 3 1 . 
2$ Figure 10 shows the instruction break status register IBS. 

Break channel number field BCN 

This field Indicates the number of channels of an instruction break. This field is read-only, and a write operation to 
30 this field is ignored. 

0000: none (reserved) 
0001: one channel 

1111:15 channels (reserved) 

Break status 0 bit BSO 

This is a status bit indicating the occurrence of an instruction address break or instruction address trace trigger. 
O: no instruction address break nor instruction address trace trigger of channel 0 
40 i : occurrence of instruction address break exception or instruction address trace trigger with the bit BE being 1 

or TE being 1 in the register IBCO indicating that the virtual address of an instruction coincides with a set address 

The bit BSO is cleared by writing 0 thereto and is set whan a BSO set signal from the break circuit 31 is asserted. 
Figure 1 1 shows the data break address 0 register DBAo. 

4S Data break address fietd DBA 

This field stores a data break address, which is a virtual address. This field is supplied to the break circuit 31 . 
Figure 12 shows the data break control 0 register DBC0. 

so Break enable bit BE (reset to 0) 

This bit specifies the validity of the data address break function. 
0: disable the data address break function 
1 : enable the data address break function 
5s if the virtual address of data to be accessed coincides with an address set in the register DBAO with the bit BE 

being 1 , a data break request is made to the processor core 20. and a bit BSO of the register DBS is set. The bit BE is 
supplied to the break drcuit 31 . 
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Trace trigger enable bit TE (reset to 0) 

This bit specifies the validity of the data address trace trigger function. 
0: disable the data address trace trigger function 
b 1 : enable the data address trace trigger function 

If the virtual address of data accessed coincides with an address set in the register DBAO with the bit TE being 
1 to indicate the enabled data address trace trigger function, the signal PCST[2;0] represents the trace trigger output 
state TST(O10) or TSQ(001) and the bit BSO of the register DBS is set, The bit TE is supplied to the break circuit 31. 
Figure 1 3 shows the data break status register DBS. 

10 

Break channel number f iafd BCN 

This field indicates the number of channels of a data break. This field is read-only, and a write operation to this field 
is ignored. 
15 0000: none (reserved) 

0001 : one channel 

1111:15 channels (reserved) 

20 Break status 0 bit BSO 

This is a status bit indicating that a data address break or data address trace trigger has occurred. 
0: no data address break or data address trace trigger of channel 0 

1 : data address break exception or data address trace trigger occurred with the virtual address of data coinciding 
25 with a set address with the bit BE being 1 or TE being 1 in the register DBCO. 

The bit BSO is cleared by writing 0 thereto and is set when a BSO set signal from the break circuit 31 Is asserted. 
Figure 14 shows the processor bus break address register PBAO. 

Processor bus break address fled PBA 

30 

This field stores a break address of the processor bus breakrtrace trigger function. This address is a physical address. 
The field PBA is supplied to the processor bus break circuit 33. 
Figure 15 shows the processor bus break data 0 register PBDO. 

36 Processor bus break data field PBD 

This field stores break data of the processor bus breakrtrace trigger function. The field PBD is supplied to the proc- 
essor bus break circuit 33. 

Figure 16 shows the processor bus mask 0 register PBM0. 

40 

Processor bus break data mask field PBM 

This field indicates bits that disable (mask) the comparison of data stored In the register PBDO according to the 
processor bus breakrtrace trigger function. 
45 0: enable the comparison of corresponding bit of the register PBDO 

1 : disable the comparison of corresponding bit of the register PBDO 
The field PBM Is supplied to the processor bus break circuit 33. 
Figure 17 shows the processor bus control 0 register PBC0. 

so Break enable bit BE (reset to 0) 

This bit specifies the vafidity of a processor bus break. 
0: disable processor bus break 
1 : enable processor bus break 

55 If an address and data coincide with set values, a debug interrupt request is made to the processor core 20. The 

bit BE Is supplied to the processor bus break circuit 33. 
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Trace trigger enable bit TE (reset to 0) 

This bit specifies the validity of a processor bus trace trigger. 
0: disable processor bus trace trigger 
6 1 : enable processor bus trace trigger 

H an address and data coincide with set values, the signal PCST[2;0] represents the trace trigger output state 
TST(01 0) or TSQ(001 ). The bit TE is supplied to the processor bus break circuit 33. 

Instruction-fetch-from-uncache-area bit IFUC 

10 

This bit specifies whether or not an address and data are compared with set values, for an instruction fetched from 
an uncache area. 

0: disable the comparison 
1 : enable the comparison 
15 The bit IFUC is supplied to the processor bus break circuit 33. 

Data-load-from-uncache-area bit DLUC 

This bit specifies whether or not the comparison of address and data is carried out according to data loaded from 
20 an uncache area. 

0: disable the comparison 
1 : enable the comparison 

The bit DLUC is supplied to the processor bus break circuit 33. 

& Data-store-to-uncache-area bit DSUC 

This bit specifies whether or not the comparison of address and data Is carried out when the data Is stored in an 
uncache area. 

0: disable the comparison 
so 1 : enable the comparison 

The bit DSUC is supplied to the processor bus break circuit 33. 

Data-store-to-cache-area bit DSCA 

35 This bit specifies whether or not the comparison of address and data is carried out when the data is stored in a 
cache area. 

0: disable the comparison 
1 : enable the comparison 

The bit DSCA is supplied to the processor break circuit 33. 
40 Figure 1 8 shows the processor bus break status register PBS. 

Break channel number field BCN 

This field indicates the number of channels of a processor bus break. 
45 0000: 0 channel (reserved) 

0001: one channel 

1111:15 channels (reserved) 

so Break status 0 bit BS0 (reset to O) 

This is a status bit indicating whether or not a processor bus break or a processor bus trace trigger has occurred. 
0: no processor bus break or processor bus trace trigger of channel 0 

1 : processor bus break or processor bus trace trigger of channel 0 with the bit BE being 1 or TE being 1 in the 
ss register PBEO 

The bit BSO is cleared by writing 0 thereto. If the bit BE is 1 , a debug interrupt request to the processor core 20 
is also cleared. The bit BSO Is set when a BSO set signal from the processor bus break circuit 33 i$ asserted. 

Figure 19 6hows the in6truction/data address break circuit 31. This circuit has an instruction address comparator 
311, a data address comparator 312. and AND circuits 313, 314, 315, and 316, 
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If the break enable bit BE or trigger enable bit TE of the register IBCO is set and il an instruction address enable 
signal from the processor core 20 is asserted, the comparator 311 compares an input instruction address from the 
processor core 20 with an address stored in the register IBAO. If they coincide with each other, the comparator 31 1 
provides a signal to set the bit BSO of the register IBS. If the bit BE of the register IBCO is set at this time, the output of 
5 the AND circuit 313 is asserted to provide the processor cord 20 with an instruction address break request. If the bit TE 
of the register IBCO is set. the output of the AND circuit 314 is asserted to provide the program counter tracer 32 with 
an instruction address trace trigger request. 

If the bit BE or TE of the register DBCO is set and if a data address enable signal from the processor core 20 is 
asserted, the comparator 312 compares an input data address from the processor core 20 with an address stored in 
io the register DBAO. If they coincide with each other, the comparator 312 provides a signal to set the bit BSO of the register 
DBS. If the bit BE of the register DBCO is set at this time, the output of the AND circuit 315 Is asserted to provide the 
processor core 20 with a data address break request, if the bit TE of the register DBCO is set the output of the AND 
circuit 316 is asserted to provide the program counter tracer 32 with a data address trace trigger request 

Figure 20 shows the details of the processor bus break circuit 33. 
15 The circuit 33 monitors a bus operation in the processor bus and provides the processor core 20 with a debug 
interrupt request it a bus operation for an address and data set in registers occur. 

The circuit 33 has a processor bus address comparator 331 , a data comparator 332 with a mask, and AND circuits 
333. 334. and 335. 

When the break enable bit BE or trigger enable bit TE of the register PBC0 is set. the comparator 331 compares 
20 an address in the processor bus with an address set in the register PBA0. The bits DSCA, DSUC. DLUC, and IFUC of 
the register PBC0 indicate the validity of comparison with respect to uncache area/cache area, data store/data load, 
and instruction fetch. The comparator 331 operates as shown in Table 2 according to a signal ID (indicating whether it 
is instruction fetch or data access), a read signal RD*, a write signal WR*. and a signal CACHE*. 
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In a read bus cycle with the read signal RD* being low, the data comparator 332 compares input data DIN[31:0] 
from the processor bus 80 with data stored in the register PBDO only for bits whose corresponding bits in the register 
PBM0 are each 0. in a write bus cycle with the write signal WR- being low, the comparator 332 compares output data 
DOLTTPI :0] of the processor bus 80 with the data stored in the register PBDO only tor bits whose corresponding bets in 
the register PBM0 are each 0. 
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If each of the outputs of the comparators 331 and 332 is high, i.e.. if the address and data coincide with the set 
address and data, the output of the AND circuit 333 is asserted to request the register circuit 35 for setting the bit BSO 
of the register PBS. tf the bit BE of the register PBCO is 6et at this lime, the output of the AND circuit 334 is asserted to 
provide the processor core 20 with a debug interrupt request, fl the bit TE of the register PBCO is set, the output of the 
5 AND circuit 335 is asserted to provide the program counter tracer 32 with a processor bus trace trigger request. 

Figure 21 shows the details of the serial monitor bus circuit 34. Tne circuit 34 has a serial monitor bus controller 
341 . a serial output circuit 342. and a serial input circuit 343. 

The serial monitor bus controller 341 receives a data output signal DOUTI31 :0], address signal A[31 :20], read signal 
RD\ write signal WFV\ coprocessor read signal CPRD*. coprocessor write signal CPWFT, and debug mode signal DM 
10 from the processor bus 60. The controller 341 also receives the clock signal CLK2 from the clock generator 37, the bit 
MP of the register DCR from the register circuit 35, and the signal 3D l from the external interface circuit 36. 

The controller 341 provides the processor bus 80 with a read acknowledge signal RDACK*. write acknowledge 
signal WRACK*, coprocessor read acknowledge signal CP RDACK*, and coprocessor write acknowledge signal 
CPWRACK\ The controller 341 provides the serial output circuit 342 with a serial monitor bus read/write signal, serial 
is monitor bus byte enable signal, serial monitor bus data signal, and for an output shift register 344 of the circuit 342, data 
load signal and output shift signal. The controller 341 provides the serial input circuit 343 with an input shift Gignal for 
an input shift register 345 and an output enable signal for an output buffer 346. The serial monitor bus read/write signal 
is high in a read bus operation and low in a write bus operation. 

When the data load signal from the controller 341 to the output shift register 344 is asserted, a start bit (fixed to 
20 low), address bits A[l] to A[19], serial monitor bus read/write signal, serial monitor bus byte enable signal, and serial 
monitor bus data signal are loaded from LSB to the output shift register 344. When the output shift signal to the register 
344 is asserted, the value in the register 344 is shifted by one bit from MSB toward LSB, and MSB is 6et to high. The 
value of LSB of the output shift register 344 is carried by an output signal SDAO. 

When the input shift signal from the controller 341 to the input shift register 345 is asserted, the value of the register 
25 345 is shifted by one bit from LSB toward MSB, and the value of the Input signal SDI is set in LSB. 

The operation of the serial monitor bus circuit 34 of Fig. 21 will be explained. 

When the processor core 20 accesses an area of OxFF20„ 00OO to 0xFF2FJ r FFF under the debug mode, or whan 
a coprocessor read/write operation (CTC0, CFC0) is executed under the debug mode, the memory in the debugger 60 
is accessed through the serial monitor bus circuit 34. In a write operation using the serial monitor bus, the circuit 34 
30 provides, as the output signal SDAO, an address signal, a bus control signal, and a data signal bit by bit in series. In a 
read operation, the circuit 34 provides, as the output signal SDAO, an address signal and a bus control signal, and 
receives data carried by the input signal SDI bit by bit in series. 

The serial monitor bus circuit 34 operates according to the clock signal CLK2, which is obtained by halving the 
frequency of the operation clock signal CLK of the processor core 20. 

35 

a) Acce66 by read/write bus operation 

In a read bus operation, the processor core 20 provides an address A[31 :0] to access and asserts the signal RD\ 
When the read acknowledge signal RDACK* is asserted, data DIN[31 :0] is read and the bus operation ends. 
40 In a write bus operation, the processor core 20 sends an address A[31 :0] to access and data DOUTI31 :0] to be 
written, and asserts the signal WR\ When ihe write acknowledge signal WRACK* is asserted, the bus operation ends. 

If the processor core 20 executes a bus operation with respect to the monitor area mentioned below under the debug 
mode, the debugger 60 Is accessed through the serial monitor bus circuit 34. 

The monitor area extends for one megabyte between 0xFF20 0000 and 0xFF2F_FFFF. 
4s (A[3l:20]) = 1111J111_0010(0:low, l:high) 

The write bus operation uses, for example, a store instruction (SW) to writ© data to the memory. The following is 
an example of the store instruction: 
sw r8 0x0004 (r9) 

In this example, a memory address is obtained by adding a 16-bK offset value 0x0004 to a general register r9. 
so To access the monitor area, the value of the general register must be set to 0xFF2OjQOO0 to OxFF2F_000O In advance. 
Tne serial monitor bus circuit 34 provides, as the output signal SDAO. the address signal A[19:2] from lower bite, 
and a high-level signal in a read operation or a low-level signal in a write operation, Thereafter, the byte enable signal 
BE[3:0]* is provided from lower bits. In a read operation, 32-bit data is received as the Input signal SDI and is provided 
as data OIN[31:0] to the processor bus 80. fn a write operation, data D0UT[31 :0] from the processor bus 60 is carried 
55 by the Output signal SDAO. 

The 18-bit address signal A[19:2] from the processor core 20 is used to access the one-megabyte memory space. 
The byte enable signal BE[3;0] of the processor core 20 is supplied to the serial monitor bus. to access a byte, a 
hatf-word, or three bytes. The serial bus, however, transfers 32-bit data D[31:0] even for byte-, half-word-, or 3-byte 
access. When writing data of one byte, half-word, or three bytes, bit positions of the signal BE[3:0] corresponding to the 
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required byte positions of the data D[31 :0] are set. In a read operation, byte positions of data corresponding to inactive 
bit positions of the signal BE[3:0] are ignored by the processor core 20. 

If the monitor area is protected in the debug mode with the bit MP of the register OCR being 1 , a write operation to 
the araa from FF20_0000 to FF2F_FFFF is ignored. In this case, the serial monitor bus circuit 34 returns only the signal 
5 WRACK" to the processor core 20, to terminate the bus operation. 

When reading the area of FF2O_O000 to FF2F_FFFF in the debug mode, correct data is read from the serial monitor 
bus irrespective of the value of the bit MR 

In the normal mode, a write operation to the monitor area of FF20.0000 to FF2F_FFFF is Ignored, and the result 
of a read operation is undefined. At this time, the serial monitor bus circuit 34 returns the signal WRACK* or RDACK" 
10 to the processor core 20 and terminates the bus operation. 

b) Access by coprocessor bu6 operation (CTCO/CFCO) 

When the instruction CFCO is executed, the processor core 20 executes a read bus operation of the coprocessor, 
is and when the Instruction CTCO is executed, a write bus operation of the coprocessor. In the coprocessor bus operation, 
the Instructions CFCO and CTCO are provided as they are to the address A[31 :0] of the processor bus as follows: 



20 


A[31»] 


COP0 


CT 


rt 


rd 


0 




A[31:0] 


COP0 


CF 


ft 


rd 


0 



CFCO (0: low level, 1 : high level) 
rt: general register 

rd: control register of coprocessor (no 
significance for serial monitor bus) 



in a coprocessor read operation, the processor core 20 asserts the signal CPRD\ and whan the coprocessor 
so read acknowledge 6ignal CPRDACK* is asserted, reads data DINpl fl] and terminates the bus operation- 

in a coprocessor write operation, the processor core 20 asserts the signal CPWR* and provides, as the data bus 
signal DOUTpi :0], the value of a general register in the processor core 20. When the coprocessor write acknowledge 
signal CPWRACK* is asserted, the processor core 20 terminates the bus operation. 

The processor core 20 carries out a coprocessor bus operation with the instructions CTCO and CFCO, to access 
35 the debugger 60 through the serial monitor bus. 

The serial monitor bus circuit 34 provides, as the output signal SDAO, bus cycle signals at the rate of a bit per clock 
period. The address signal A[19:2] of the processor core 20 is provided from lower bits. Thereafter, a high-level signal 
is provided in the coprocessor read operation, and in the coprocessor write operation, a low-level signal is provided. A 
byte anabl e signal in the serial monitor bus is a low-level signal for four clock periods without regard to the signal BE[3:0) 
40 of the processor bus. 

In response to the instruction CFCO, 32-bit data is received as the input signal SOI, which is supplied as the data 
signal DIN[31 :0] to the processor bu6. In response to the instruction CTCO, the data output signal DOUTI31 :0] from the 
processor bus is supplied as the output signal SDAO. 

In the debug mode, a write Operation of the serial monitor bus is carried out according to the instruction CTCO 
45 irrespective of the protection of the monitor area, i.e., irrespective of the value of the bit MP of the register DCR. Also, 
a read operation of the serial monitor bus is carried out according to the instruction CFCO. 

In the normal mode, the write operation according to the instruction CTCO is ignored, and the result of the read 
operation according to the instruction CFCO is undefined. The debug module returns only the signals CPRDAW and 
CDWRACfC to the processor core 20 and terminates the bus operation. 
so Timing charts of the serial monitor bus operations will be explained. 

a) Read operation of serial monitor bus 

Figure 22 is a timing chart showing a read operation of the serial monitor bus. 

55 

(1) in cycle 1 , the processor core 20 starts the read operation to the area of 0xFF20_0000to0xFF2F_FFFF (A[31 :20] 
■ 1 1 1 U 1 1 1.0010), The processor core 20 provides an address A[31 :0] to access and asserts the signal RD*, 
The byte enable signal BE[3;0] for byte positions to be read is asserted. 
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25, the output signal SDAO becomes low for tour clock periods wfthout regard to the byte enable signal of the 
processor bus. In cycles 26 to 57, the output signal SDAO provides data bus output bite DOUT[0] to DOUT[31]. 
(4) In cycle n. the debugger 60 finishes the writing of the data and provides, as the input signal SDL a low-level 
signal for a clock period. 

s (5) In cycle n+1, the circuit 34 detects the tow-level signal and asserts the coprocessor write acknowledge signal 
CPWRACK* to the processor core 20. 

(6) in cycle rv+1, the processor core 20 completes the coprocessor write bus operation. 

Figure 26 is a flowchart showing the operation of the serial monitor bU6 controller 341 , 
10 The controller 341 monitors the operations of the processor bus 60. 

(1) In steps S120, S124, and S125, a read operation of the serial monitor bus 6tarts because an address A[31 :20] 
indicates QxFF2, the read signal RD* is asserted (low), and the signal DM is high to indicate the debug mode. 

(2) In steps S120, $124, S132. and Si 33, the signal RDACK" of the processor core 20 is asserted to terminate the 
is bus operation because the signal DM is low to indicate the normal mode, although A[3 1 :20] « 0xFF2 and the signal 

RD" is asserted (low). 

(3) In steps S120, S121, $126, and S127, a write operation of the serial monitor bus starts because A[312Q] = 
0xFF2, the write signal WR* is asserted (low), the signal DM is high to Indicate the debug mode, and the bit MP of 
the register OCR Is 0 to indicate a write enable state. 

(4) Insteps $120, S1 21, Si 26, $134, and $135, the signal WRACK* of the processor core 20 is asserted to terminate 
the bus operation because the signal DM is lew to indicate the normal mode or the bit MP of the register DCR is 1 
to indicate a write prohibited state, although A[31 ;20] = 0xFF2 and the write signal WR* is asserted (low). 

(5) In steps $120. S121, S122, $128. and $129, a coprocessor read operation of the serial monitor bus starts 
because A[31 51] = 0100_0000_010, the coprocessor read bus operation signal CPRD* for the instruction CFC0 

2s is asserted (low), and the signal DM is high to indicate the debug mode. 

(6) In steps S120, S121, $122, S128. S136. and S137, the signal CPRDACK* of the processor core 20 is asserted 
to terminate the bus operation because the signal DM is lew to indicate the normal mode, although AJ31;21] = 
0100_0000_O1O and the signal CPRD* for the instruction CFCO is asserted (low). 

(7) In steps S120. S121, S122, S123, $130, and S131. the coprocessor read operation of the 6erial monitor bus 
so starts because A[31 :21] = 0100_COOO_1 1 0. the coprocessor write bus operation signal CPWR* for the instruction 

CTC0 is asserted (low), and the signal DM is high to indicate the debug mode. 

(8) In steps S120, S1 21 , S122, Sl23, S138, and S139, the signal CPWRACK" of the processor core 20 is asserted 
to terminate the bus operation because the signal DM is low to indicate the normal mode, although A[31:21] = 
0100_0000„1 10 and the signal CPWR* for the instruction CTC0 is asserted (low). 

Figure 27 is a flowchart showing the read operation of the serial monitor bus circuit 34. 

In the read operation, the serial monitor bus controller 341 provides, in cycle 1 . the output shift register 344 with a 
high-level serial monitor bus read/write signal, a serial monitor bus byte enable signal BE[3:0J, and a high-level serial 
monitor bus data signal, and asserts a data load signal, 
w In a coprocessor read bus operation according to the instruction CFCO. the serial monitor bus controller341 provides 
the output shift register 344 with a high-level serial monitor bus read/write signal, a low-level byte enable signal, and a 
high-level serial monitor bus data signal, and asserts the data load signal. The shift register 344 latches these values 
and a low level at an LS6. 

The output signal $BAO is set to low. The controller 341 asserts the output shift signal in cycle 2. 

In cycles 3 to 25, the controller 341 asserts the output shift signal. The bits latched by the register 344 in cycle 1 
are supplied as the output signal SDAO at the rate of a bit per clock period. 

In cycles 26 to n, the controller 341 waits for the input signal $DI being asserted to low. 

In cycles n+l to n+32, the controller 341 asserts the input shift signal to the serial input circuit 343, and the input 
signal SDI carries input data D[Q] to D[31] to the input shift register 345. 
>0 In cycle n+33. the controller 341 asserts the read acknowledge signal RDACK" of the processor bus in the read 
operation. In the coprocessor read bus operation, the controller 341 asserts the coprocessor read acknowledge signal 
CP RDACK'. The output enable signal to the serial input circuit 343 is asserted, and the data D[31 :0] in the input shift 
register 345 is carried by the data bus input signal DIN[31 :0]. 

Figure 28 is a flowchart showing the write operation of the serial monitor bus circuit 34. 
s In the write operation, the serial monitor bus controller 341 provides, in cycle 1. the output shift register 344 with 
the tow-level serial monitor bus read/Write signal, seriaJ monitor bus byte enable signal BEp3:0]. and serial monitor bus 
data signal DOUT[3l :o], and asserts the data load signal. 

in the coprocessor write bus operation according to the instruction CTC0. the controller 341 provides the register 
344 with the low^evel serial monitor bus readAwite signal, low-level 4-btt serial monitor bus byte enable signal, and serial 
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monitor bus data signal DOUT[31 :0] ( and asserts the data load signal. The register 344 latches these values and a low 
level at an LSB in cycle 1 . 

In cycle 2, the output signal SDAO is set to low. The controller 341 asserts the output shift signal. 

In cycles 3 to 57, the controller 341 asserts the output shift signal. The values latched by the register 344 in the 
5 cyde 1 are carried by the output signal SDAO at the rate of a bit per clock period. 

In cycles 58 to n, the controller 341 waits for the input signal $01 being asserted to low. 

In cycle n+1, the controller 341 asserts the write acknowledge signal WRACK* to the processor bus in the write 
operation. If it is the coprocessor bus operation, the controller 341 asserts the coprocessor write acknowledge signal 
CFWRACK*. 

to The program counter tracer 32 will be explained. 

An indirect jump, a direct jump, and a branching are defined as follows; 

Indirect jump 

is A value stored in a register or memory is used as the target address of a jump. Namely, a jump instruction itself 
does not specify the target address of the jump. 

Direct jump 

so The target address of a jump instruction is specified by a program counter and a code contained in the instruction. 
Branching (or conditional branching) 

This is a jump instruction whose destination is specified by a program counter and the sum of parts of codes con- 
25 tained in the instruction. Whether or not the branching is actually carried out is determined according to conditions. If 
the branching is actually carried out, it is called 'branch taken." and if it is not carried out, it is called "branch not taken." 

Figure 29 shows the details of the program counter tracer 32. The tracer 32 receives the following signals from the 
processor core 20: 

30 Qebug mode signal DM 

This signal indicates whether the current mode is the debug mode or normal mode. 

Pipeline execution signal 

35 

This signal indicates the execution of an instruction. 

30-bit target program counter [31 2] signal 

40 This signal indicates the target address of a branch Instruction or jump instruction, or the vector address of an 
exception and is enabled when the below-mentioned indirect jump signal, direct jump signal , branch taken signal, excep- 
tion caused signal are asserted. 

Indirect jump signal 

45 

This signal indicates that an indirect lump has been executed. 
Direct jump signal 
so This signal indicates that a direct jump has been executed. 
Branch taken signal 

This signal indicates that a branch instruction has been executed and taken. 

55 

Exception caused signal 

This signal indicates that an exception has occurred. 

The tracer 32 provides the processor core 20 with the following signals to completely trace the program counter: 
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Pipeline stall request signal 

This signal stalls a pipeline process or the processor core 20. to completely let the target program counter provide 
an output. H the next indirect jump occurs while the tracer 32 is receiving the target program counter signal of an indirect 
s jump, the tracer 32 asserts the pipeline stall request signal to stall a pipeline process of the processor core 20- Once 
the target program counter 6lgnal completes, the pipeline stall request signal Is negated to resume the pipeline process. 

The tracer 32 receives a trigger request from the instruction/data address break circuit 31 or from the processor 
bus break circuit 33. The tracer 32 receives the bit TM of the register OCR and the debug enable signal DBGE*. If the 
signal DBGE* is asserted to low, it indicates that the debugger 60 is valid. 
10 The tracer 32 converts program counter trace information provided by the processor core 20 under the normal mode 
into a one-bit program counter output TPC and a 3 -bit status signal PCST[2:0], which are supplied to the debugger 60. 

The signate PCST[2:0] and TPC will be explained. 

a) PCST[2:0] 

The execution state of an instruction is carried by the 6ignal PCST[2:0] at the rate of a bit per clock period. (0: low. 
1 : high) 

111: pipeline stall state (STL) 

This state Indicates that the execution of an instruction has not been finished when there is no trace trigger 
so request. 

1 10: branch/jump taken slate (JMP) (with program counter output) 

This state indicates that a taken branch or jump instruction has been executed, and the target address thereof is 
going to be carried by the signal TPC. 

101 ; branch/jump taken 6tate (BRT) (without program counter output) 
25 This state indicates that a taken branch or direct jump instruction has been executed, and no target address is 

carried by the signal TPC- 

100: exception state (EXP) (with exception vector code output) 

This state Indicates that an exception has occurred and that an exception vector code is going to be carried by 
the signal TPC. 

30 Oil: sequential execution state (SEQ) (Instruction execution) 

This statB indicates that an instruction has been executed not under the state JMP, BRT, or TSQ. This state is 
also established when a branch instruction has not been taken. 
010; trace trigger output state (T$T) in pipeline stall 

This state indicates that an address trace trigger or processor bus trace trigger has occurred in a clock where an 
35 instruction is still being executed. 

001: trace trigger output state (TSQ) In execution 

Thte state indicates that an address trace trigger or processor bus trace trigger has occurred in a clock where 
the execution of an instruction is complete. 
000: debug mode (DBM) 
40 This state is unachievable under the normal mode. 

The signal TPC is used to provide the target address of a branch or jump instruction, in a dock where the signal 
PC$T[2:Q] indicates the state "1 10" (JMP), the target address is provided from a lower bit A(2) at ihe rate of a bit per 
Clock period. In a clock where the signal PCSTT2:0] indicates the state "100" (EXP), a 3-bit exception vector code is 
provided 1rom lower bits in order of code(0), code(i), and code(2) at the rate of a bK per clock period. The exception 
4$ vector address and 3 -bit code are as follows: 





Vector address 


Code (2:0) 


Reset Nmi 


BFC0JJ000 


4(100) 


UTLB (BEV=0) 


9000.0000 


0(000) 


UTLB (BEV=1) 


BFC0_0100 


6(110) 


Other (BEV-0) 


eooo_ooao 


1(001) 


Other (BEV=1) 


Bpcojneo 


7(111) 
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Since a target address is carried by the signal TPC bit by bit in series, the next branch instruction, jump instruction, 
or exception may occur while the current branch^ ump instruction is carried by the signal TPC. The priority of target 
addresses carried by the signal TPC is as follows: 

6 a) If a new indirect jump instruction occurs while a target program counter signal is being provided, this target 

program counter signal is terminated, and a target program counter signal for the new indirect jump instruction is 
started. 

b) rf an exception occurs while a target program counter signal is being provided, the target program counter signal 
Is suspended, the 3-bit vector number of the exception is provided, and thereafter, the suspended signal is resumed. 
10 c) If a new direct jump or branch instruction occurs while a target program counter signal is being provided, the 
target address of the direct jump or branch instruction is not provided. Only when the target program counter signal 
is not being provided, a target program counter signal for the direct jump or branch instruction is provided. 

Examples of program counter tracing outputs will be explained with reference to the drawings. 

15 

(Example 1) Program counter tracing of branch instruction 

Figure 30 shows an example of a program counter tracing signal for a branch instruction. 

When a first taken branch instruction "beq" i6 executed, the output signal TPC is not carrying a target program 
20 counter signal Accordingly the signal PCSTI2:0] indicates the state JMP f and the signal TPC start carrying a target 
program counter signal for the instruction "beq." in response to a not-taken branch instruction "bne," the signal PCST[2:Q] 
indicates the code SEQ. In response to a second taken branch instruction *bne, H no target program counter signal is 
carried by the signal TPC because the signal TPC is carrying the target program counter signal for the first branch 
instruction "beq." At this time, the signal PCST]2:0] indicates the state BRT. 

26 

(Example 2) Program counter tracing of indirect jump instruction 

Figure 31 shows an example of a program counter tracing signal for an indirect jump instruction. 

tn response to a first indirect jump Instruction "Jrl ,* the signal PCSTI2:0] indicates the state JMP, and the signal TPC 
30 starts to carry a target program counter signal. In response to a not-taken branch instruction Tone,", the signal PCST[2:0] 
indicates the state SEQ. In response to a second indirect jump instruction "jr2," the signal TPC stops to carry the target" 
program counter signal for the first indirect jump instruction "jrl" and starts to carry a target program counter signal for 
the second instruction "jr2." At this time, the signal PCST[2;0] indicates the state JMP. 

ss (Example 3) Program counter tracing of exception and indirect jump instruction 

Figure 32 shows an example of a program counter tracing for an exception and Indirect jump instruction. 

In response to a software break instruction break." an exception occurs, and the signal PCST[2:0] indicates the 
state EXP At this time, the signal TPC starts to carry an exception vector code. At a not-taken branch instruction "bne," 
40 the signal PCST{2:0] indicates the state SEQ. At an indirect jump instruction "jr2," the signal TPCcarries a target program 
counter signal for this instruction "jr2," and the signal PCSTg:0] indicates the state JMP . 

The trace trigger state TSQ or TST of the signal PCST[2:0] will be explained. 

When the coincidence of an address and data occurs in a bus cycle, an instruction/data address break or a processor 
bus break occurs to cause the signal PCST[2:0] to indicate the state TSQ or TST 
45 When an instruction address trace trigger request, data address trace trigger request, or processor bus trace trigger 
request is made, the 6ignal PCST[2:0] indicates the state TSQ or TST. If the signal PCST[2:0] indicates the state JMP, 
BRT. or EXP. the state TSQ or TST will be delayed. H there is no trace trigger request, the signal PCST[2:0] may indicate 
the state TSQ or TST in a dock period where the signal PCST[2:0] is going to indicate the state SEQ or STL 

so (a) instruction/data address trace trigger 

When an instruction/data address trace trigger occurs, the signal PCST[2;0] indicates the state TSQ. If a trace 
trigger is caused by a taken branch instruction, a jump instruction, or an instruction that doe6 not cause the signal 
PCST[2;0] to indicate the state SEQ, the output of the trace trigger is delayed. If there is no trace trigger request, the 
ss signal PCST[2:0] indicates the state TSQ or TST in a dock where the signal PCST[2:0] is scheduled to indicate the state 
SEQ or STL 
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(Example 1) Example of instruction/data address trace trigger 

Figure 33 shows an example of art instruction/data address trace trigger. 

In response to an instruction "add" that causes an instruction trace trigger or a data address trace trigger, the signal 
s PCST[2;0] indicates the state TSQ. 

(Example 2) Example of instruction/data address trace trigger due to exception 

Figure 34 shows an example of an instruction/data address trace trigger due to an exception. 
10 If a software break instruction "break" causes an instruction address trace trigger or a data address trace trigger, 
the signal PCST[2;0] Indicates the state EXP, and in the next dock, the trace trigger state TST for a pipeline stall. 

(Example 3) Example of instruction/data address trace trigger due to indirect jump instruction 

is Figure 35 shows an example of an instruction/data address trace trigger due to an indirect jump instruction. 

When an indirect jump instruction -Jr2" causes an instructor! address trace trigger or a data address trace trigger, 
the signal PCST[2;0] indicates the state JMP, and in the next dock, the trace trigger state TSQ for an instruction execution 
condition. 

20 (b) Processor bus trace trigger 

When a processor bus trace trigger request is made, the signal PC ST[2:0] indicates the state TSQ or TST. if the 
signal PCST[2:0] Is indicating the state JMP, BRT, or EXP, the trace trigger state TSQ or TST is delayed. When there is 
no trace trigger request the signal PCST[2:0) indicates the state TSQ or TST in a clock where the signal PCST[2:0] is 
25 scheduled to indicate the state SEQ or STL 

The generation of the debug mode state DBM will be explained. 

if the processor core 20 causes a debug exception or a debug reset the debug mode signal DM is asserted to high 
to enter the debug mode. Then, the tracer 32 provides the signal PCST[2:0] indicating the debug mode state DBM. 

Figure 36 shows the output timing of the signal PCSTI2:0] when a debug exception occurs. 
30 When no target program counter signal is provided, the debug mode starts just after the end of the instruction that 
has caused the debug exception. The program counter trace information just before the occurrence of the debug excep- 
tion is provided. 

Figure 37 shows the timing of the signal PCSTI2:0] when a target program counter signal is being provided when 
a debug exception occurs. 

95 In this case, the debug mode starts after the completion of the target program counter signal. Program counter trace 
information up to an instruction just before the occurrence of the debug exception is provided. While the target program 
counter signal is being provided, the signal PC$T[2:0] indicates the state STL. 

Figure 38 shows the timing of the signal PCSTI2:01 when returning from the debug mode. 
The debug mode continues until a branch delay slot instruction of a return instruction DEBET Irom a debug exception 
40 or debug mode is provided. The normal mode starts from an instruction that is a target of the instruction DERET, to 
enable program counter tracing. 

Returning to Fig. 29, the tracer 32 will be explained. 

The tracer 32 has a program counter trace controller 321 , a target program counter shift register 322, an exception 
vector coder 323, an exception code shift register 324, and a selector 325. 
45 The controller 321 has an exception code output status bit 326 and a target program counter output counter 329. 
The operation of the tracer 321 will be explained. 

Table 3 shows the oulputs of the signal PCST[2:0] when the bit TM of the register DCR is 0- in Table 3. "1 - indicate 
an active state and V indicates a "don't care" state. 

50 



55 
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Table 3 



5 


Debug mode 
signal DM 


0 


0 


0 


0 


0 


0 


0 


0 


1 


1 




indirect jump 
signal 


0 


0 


0 


0 


0 


1 


0 


0 


X 


X 


10 


Direct jump 
signal 


0 


0 


0 


0 


1 


0 


0 


0 


X 


X 




Branch taken 
signal 


0 


0 


0 


1 


0 


0 


0 


0 


X 


X 


IS 


Exception 

occurrence 

signal 


0 


0 


1 


0 


0 


0 


0 


0 


X 


X 




Pipeline exe- 
cution signal 


0 


1 


1 


1 


1 


1 


0 


1 


X 


X 


ZQ 


Trigger 

request signal 


0 


0 


X 


X 


X 


X 


1 


1 


1 


0 


25 


Providing 
TPC or excep- 
tion code 
(internal 
state) 


x 


X 


X 


10 


1 


0 


X 


X 


X 


X 


1 0 




PCSTI2:0] 
output 


STL 


SEQ 


EXP 


BRTJMP 


BRT 


JMP 


JMP 


TST 


TSQ 


TST 


STL DBM 



$0 



In this table* the trigger request signal is the OR of en instruction address trace trigger request signal, data address 
trace trigger request signal, and processor bus trace trigger request signal. 
35 When the 5-bit counter 327 ts not 0, it indicates that the signal TPC Is being provided. When the exception code 
output status bit 326 is 1 , an exception vector code is being provided. In Table 3, the internal state "outputting TPC or 
exception code* win be 1 if the counter 327 is not 0, or If the exception code output status bit 326 is 1 . The counter 327 
is updated as follows: 

40 (1) When the signal TPC is not carrying a target program counter signal, or when a new program counter signal is 
going to be provided, the counter 327 is cleared to 0. 

(2) When the signal TPC is carrying an exception vector, the interna! status indicating that the program counter 
signal is being provided and the counter 327 are kept as they are. 

(3) When the counter 327 reaches 30, the counter 327 is zeroed- This indicates that the output of the target program 
46 counter is complete. 

(4) In a case other than the above cases (1). (2), and (3), the counter 327 is incremented by one. At this time, the 
signal PTC is carrying the target program counter signal. 

When an exception occurs, the exception code output status bit 326 asserts, for three clock periods, an internal 
so state indicating that an exception code is being provided. When the status bit 326 is asserted, an exception code shift 
signal and exception code output switch signal are asserted. An exception code load signal is asserted when the signal 
PCST[2:0] indicates the state EXP. At ihis time, the output of the exception vector coder 323 is loaded to the exception 
code shift register 324. A target program counter load signal is asserted, and the signal PCST[2:0] indicates the state 
JMP. Then, the value of the target program counter is loaded to the target program counter shift register 322. The target 
55 program counter shift 6ignal is asserted when the counter 327 is not 0 and when the status bit 326 ie not asserted. 

When the bit TM of the register OCR is 1 . a program counter trace is completely carried out. If the signal DBGE" is 
asserted, the bit TM is set, and the next indirect jump occurs while the target program counter signal for an indirect jump 
is being provided, the controller 321 asserts a pipeline stall request signal to stall a pipeline process of the processor 
core 20. When the current target program counter is completely provided, the pipeline stall request signal is negated to 
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resume the pipeline process. 

Table 4 shows the output of the signal PCST[2:0] with the bit TM being 1 . In Table 4, "1 " indicates an active state, 
and V indicates a "donl care" state. 



Table 4 



Debug mode 
signal DM 


0 


0 


0 


0 


0 


0 


0 


0 


1 


1 


Indirect jump 
signal 


0 


0 


0 


0 


0 


1 


0 


0 


X 


X 


Direct jump sig- 
nal 


0 


0 


0 


0 


1 


0 


0 


0 


X 


X 


Branch taken 
signal 


0 


0 


0 


1 


0 


0 


0 


0 


X 


X 


Exception 
occurrence sig- 
nal 


0 


0 


1 


0 


0 


0 


0 


0 


X 


X 


Pipeline execu- 
tion signal 


0 


1 


1 


1 


1 


1 


0 


1 


X 


X 


Trigger request 
signal 


0 


0 


X 


X 


X 


X 


1 


1 


1 


< 


) 


Providing tar- 
get program 
counter or 
exception code 
(internal state) 


X 


X 


X 


1 


0 


1 


0 


1 


0 


X 


X 


X 


1 


0 


PCST[2:0] out- 
put 


STL 


sea 


EXP 


BRT 


JMP 


BRT 


JMP 


STL 


JMP 


TST 


TSQ 


TST 


STL 


DBM 


Pipeline stall 
request signal 


0 


0 


0 


0 


0 


0 


0 


1 


0 


0 


0 


0 


0 


0 



When an indirect jump signal becomes active due to the execution of an indirect jump while the target program 
counter signal or exception code is being provided, the pipeline stall request signal to the processor core 20 is activated. 
40 The internal stale indicating that the larget program counter signal or exception code is being provided becomes active 
for 30 clock periods after the start of the target program counter signal 

The target program counter shift register 322 loads the value of a target program counter output when the target 
program counter load signal from the controller 321 is asserted. The register 322 shifts its value from MSB toward L$B 
by one bit when the target program counter shift signal from the controller 321 Is asserted. 
46 The exceplion vector coder 323 encodes an exception vector address according to bits A[29], A[s], and A[7] of the 
vector address as follows : 
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vector address (A29, AS, A7) 


Code 


Reset, Nmi 


BFCO_O00O(1O0) 


4 


UTLB (BEV=0) 


8O00_OOO0 (000) 


0 


UTLB (BEV-1) 


BFCO_0100 (110) 


6 


Other (BEV=0) 


sooo_ooeo (001) 


1 


Other (BEV=1) 


8FCO_0180 (111) 


7 



75 The coder 323 provides the exception code shift register 324 with the address bits A[29], A(8], and A[7] of the target 
program counter output 

The register 324 loads the exception vector code from the coder 323 when an exception code toad signal from the 
controller 321 is asserted. When an exception coda shift 6ignal from the controller 321 is asserted the value of the 
exception code shift register 324 is shifted trom MSB toward LSB by one bit. 
20 The selector 325 provides the signal TPC with the LSB of the register 324 when an exception code output switch 
signal from the controller 321 is asserted. When the exception code output switch signal is negated, the selector 325 
provides the signal TPC with the LSB of the register 322. 

The operation of the tracer 32 wil] be explained with reference to timing charts. 

Figure 39 shows the operation of the tracer 32 when a target program counter signal is provided. 
25 When the counter 327 holds 0 and when an indirect jump signal, direct jump signal, or taken branch signal is 
asserted, the controller 321 asserts the target program counter load 6ignal. 

In the next clock, the LSB, i.e., A[2] of the target address loaded to the register 322 is supplied to the 6ignal TPC. 
At the same time, the signal PCST[2:0] indicates the state J MP, and the controller 321 asserts the target program counter 
shift signal. As a result, the register 322 Is shifted by one bit from MSB toward LSB, and the bit A[3] is provided to the 
30 signal TPC in the next clock. The target program counter shift 6»gnal is continuously asserted to provide the signal TPC 
with the program counter output until the counter 327 count6 30. When the counter 327 counts 30, the counter 327 is 
cleared to 0, and the target program counter shift signal is negated to terminate the target program counter output to 
the signal TPC 

Figure 40 shows the operation oi the tracer 32 when the next indirect jump occurs while a target program counter 
35 signal is being provided. 

When the second indirect jump occurs, the counter 327 is cleared to 0, and the target program counter load signal 
is asserted, in the next clock, the LSB, i.e.. bit A[2] of the target address loaded to the register 322 is provided to the 
signal TPC At the same time, the signal PCST[2:0] indicates the state JMP, and the controller 321 asserts the target 
program counter shift signal. From the next dock, the target address is provided to the signal TPC every cycle. 
40 Figure 41 shows operation timing when an exception occurs while a target program counter signal is being provided, 
if the exception occurrence signal is asserted while a target program counter signal is being provided, the exception 
code load signal is asserted to load the exception code to the exception code shift register 324. From the next clock, 
the exception code output status bit 326, exception code shift 6ignal ( and exception code output switch signal are 
asserted. The exception code is provided for three clock periods. During this periods, the target program counter shift 
45 signal is negated. When the status bit 326 and exception code switch signal are negated, the target program counter 
signal is again carried by the signal TPC 

Figure 42 shows the details of the external Interface circuit 36. 

The external interface circuit 36 has a DBM code detector 361 , selectors 362 and 363, mask circuits 334, 365. and 
366. output buffers 367A, 367B, and 367C, pull-up resistor input buffers 368A, 3S8B, and 368C, and input buffers 3 69 A 
so and 369B. 

The DBM code detector 361 asserts an output signal when the signal PC$T[2:0] indicates the debug mode state 
DBM (000). 

The selector 362 provides the frequency-divided clock signal CLK2 when the output of the DBM code detector 361 
is asserted, i.e., when it is the debug mode, and provides the core clock signal CLK when the output of the DBM code 
ss detector 361 is negated, i.e., when it is the normal mode. 

The selector 363 provides the output SDAO of the serial monitor bus circuit 34 when the output of the DBM coda 
detector 361 is asserted, i.e., when it is the debug mode, and provides the 6ignal TPC of the tracer 32 when the output 
of the DBM code detector 361 is negated, i.e., when it is the normal mode. 
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In the debug mode, the mask circuit 364 masks the external input signal DINT7SDI so that the input signal DINT* 
to the processor core 20 is always negated. 

When the bit Mint of the register DCH is 0, the mask circuit 366 sets the signal lnt[5:Oj to the processor core 20, to 

mask an interrupt. t . . „ 

s When the bit MRst of the register DCR Is 0, the mask circuit 366 masks the user reset signal RESET during the 

execution of a debug exception handler (the signal DM being high) . 

The output buffer 367A provides the output of the selector 362 outside as the signal DCLK. The output buffer 367B 

provides the output of the selector 363 outside as the signal TPC/SDAO- The output buffer 367C provides the signal 

PCST[2:0] of the tracer 32 outside as the external signal PCST[2:0], 
10 The pull-up resistor input buffer 368A receives the external signal DINT7SDI. Since this buffer has a pull-up resistor, 

the output thereof is always high when the external signal DINT7SDI is disconnected. The pull-up resistor input buffer 

3669 receives the external signal DBGE*. Since this buffer has a pull-up resistor, the output thereof Is always high H the 

external signal DBGE" is disconnected. The pull-up resistor input buffer 368C receives the external signal D RESET*. 

Since this buffer has a pull-up resistor, the output thereof is always high if the external signal D RE SET* is disconnected, 
75 These external signals D 1NT7SDI, DBGE*, and DRESET* are disconnected when the debugger 60 is disconnected. 

Then, these signals form high-level internaJ signals, and the functions of the debug module are disabled. 

The input buffer 369A receives the external interrupt signal INT[5;0] r . The input buffer 369B receives the external 

user reset signal RESET*. 

Figure 44 shows a microprocessor and debug system acoording to another embodiment of the present invention. 
20 This embodiment is characterized in that the microprocessor 10 incorporates a memory 90 and a peripheral circuit 
1 00. Other arrangements of this embodiment are the same as those of the first embodiment. 

A processor core 20 reads a program out of the memory 90 through an internal processor bus 30, executes the 
read program, reads or writes data from or to the memory 90. and accesses the peripheral circuit 100. Under a debug 
mode, the processor core 20 executes a monitor program of a debugger 60 through a debug module 30. 

It the functions and timing of interface signals of the debug module 30 and debugger 60 are equal to one another, 
the debugger 60 of the first embodiment will be U6ed for the second embodiment irrespective of the difference of the 
incorporated memory 90 and peripheral circuit 100. 

If the functions of the processor core 20 of the second embodiment are the same as those of the first embodiment, 
the same monitor program as that of the first embodiment will be used for the second embodiment 
so The above two embodiments employ each an instruction/data address break channel and a processor bus break 
channel. The present invention ie not limited to this arrangement but may employ two or more channels. Figure 43 shows 
a register IBS involving 1 5 instruction address break channels. 

The above two embodiments employ each a serial monitor bus having a bit width of one. The present invention is 
not limited to this arrangement. The bit width may be two or more if many microprocessor external signals are used for 
35 a serial monitor bus. 

The above two embodiments employ each an external signal for carrying the output of a target program counter. 
The present invention is not limited to this arrangement. The output of a target program counter may be carried by a 
plurality of external signals H they are available. 

According to the above two embodiments, the clock generator 37 halves me frequency of the dock signal CLK for 
40 the processor core. The present Invention is not limited to this. The frequency ol the dock signal for the serial monitor 
bus circuit may be the same as that of the clock 6ignal CLK or an integer multiple or a power of 2 of that of the clock 
signal CLK. 

As explained above, the present Invention is capable of sharing the hardware of a debug tool with many functions 
and reducing the number of signals connected to the debug tool. The prior art must employ, tor example, 30 address 
45 signals, 4 byte enable signals, a read signal, a write signal, a read acknowledge signal, a write acknowledge signal, and 
32 data signals, i.e., 70 signals in total to connect a user target system to a debugger. On the other hand, the present 
invention requires only eight signals to connect a user target system to a debugger. This results in minimizing the number 
of probes and reducing costs. 

According to the present invention, a microprocessor on a user target system accesses memories and I/O units, to 
so ease conditions on the timing of a debug tool. Signals that are not connected to the debug tool are not influenced by 
debugging. The present invention is capable of slowing a communication speed between a debug tool and a microproc- 
essor if the operation speed of the microprocessor is too high. 

Compared with the prior art of Fig. 2, the present invention stores a monitor program in a memory on a debug tool 
without using user memories. To start monitoring a target system, the present invention employs a dedicated debug 
& exception and debug reset without restricting user interrupts. A user target system is not required to have a serial interface 
for debugging. The present invention is capable of using a hardware break point 

Compared with the prior art of Fig. 3, the present invention does not require a sequencer to be installed in a micro- 
processor, to ther^iy simplify a logic circuit for debugging. Since the present invention employe a monitor program to 
access registers, additional registers are accessible only by modifying the monitor program. 
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!n summary, the present invention provides a microprocessor of a user target system with a debugging function, to 
reduce signals tor connecting the target system with a debugger During debugging, the present invention operates the 
microprocessor of the target system, to easily access memories and I/O units of the target system. 

According to the present invention, control registers in the debug tool and debug module are inaccessible during 
the execution of a user program under a normal mode, so that the memories and registers of the debug tod will never 
be destroyed by the user program, to thereby improve the reliability of the system. 

The present invention prohibits accessing the control registers of the debug tool and debug module even after the 
debug mode is started. If a write operation of the user program to the control register of the debug tool or debug module 
is incomplete when a debug exception to start the debug mode occurs, the write operation is prohibited by setting the 
bit MP of the register DCFV This prevents the memories and registers of the debug tool from being mistakenly broken 
by the user program, to thereby improve the reliability of the debug system. 

According to the present invention, a write operation to the debug tool according to an instruction CTCO under the 
debug mode is always allowed without regard to the value of the bit MR Since the address of a monitor area is prepared 
separately from a memory write instruction, it is not necessary to use a general register. 

Accordingly, the contents of the general register will never be broken by the write operation, and the value of the 
general register can be saved in the memory of the debug tool just after the occurrence of a debug exception. In this 
way, the debug tool of the present invention never destroys the contents of users general registers, to realize good 
transparency of the debug system. 

The present invention provides a microprocessor of a user target system with a debugging function, to eliminate an 
interface signal tor carrying a program counter trace output 

The present invention provides a microprocessor of a user target system with a debugging function and realizes a 
trigger function with minimum hardware. 

Various modifications will become possible for those skilled in the art after receiving the teachings of the present 
disclosure without departing from the scope thereof. 

Claims 

1 . A microprocessor comprising: 

a processor core for executing a user program and a monitor program for debugging a user target system; 

and 

a debug module connected to said processor core through at least one of an internal debug interface and a 
processor bus, having interface means serving as an interface with a debug tool so that said processor core may 
execute the monitor program, and control means for requesting said processor core for one of an interrupt and an 
exception to swhch said processor core from the user program to the monitor program. 

2. A debug system comprising: 

a debug tool having a monitor program for debugging a user target system; 

a microprocessor having a processor core for executing one of a user program and the monitor program and 
a debug module connected to the processor core through at least one of an internal debug interface and a processor 
bus and to said debug tool through an external debug interface, the debug module having interface means serving 
as an interface with said debug tool so that the processor core may execute the monitor program and control means 
for requesting the processor core for one of an interrupt and an execution to switch the processor core from the user 
program to the monitor program; 

a memory connected to said microprocessor through the processor bus In the user target system, for storing 
information necessary for said microprocessor to execute the user program; and 

an I/O unit connected to said microprocessor through the processor bus in the user target system. 

3. The microprocessor according to daim 1 , wherein said debug module has: 

a break circuit tor comparing the address of an instruction or data provided by said processor core with a 
preset address or data, and if they coincide with each other, sending an address break exception request to said 
processor core; 

a tracer for processing program counter trace information provided by said processor core and providing the 
processed information; 

a processor bus break circuit connected to said processor core through the processor bus, for monitoring 
bus cycles in the processor bus, and if a bus cycle for preset address and data is executed, sending an exception 
request to 6aid processor core; 

a serial monitor bus circuit connected to said processor core through the processor bU6, serving as an inter- 
face with the debug tool when said processor core executes the monitor program stored in the debug tool; 

a register circuit tor storing information to control the functions of said debug module, the information being 
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accessed by said processor core; 

an external interface circuit serving as an interface for the tracer, serial monitor bus circuit, and processor 
core with the debug tool; and 

a clock signal generator for providing the debug tool with a dock signal that defines the transfer speed of 
5 signals transmitted between the microprocessor and the debug tool. 

4. The microprocessor according to claim 3. wherein the clock signal generator supplied a docksignal wnose frequency 
is a multiple of or a power of 2 ol the frequency of a clock signal that drives said processor core. 

19 5. The microprocessor according to claim 1 . wherein said debug module i6 connected to the debug tool with dedicated 

signals. 

6. The microprocessor according to claim 1 , wherein said debug module is connected to the debug tool with unidirec- 
tional signals. 

75 

7. The microprocessor according to claim 1 , wherein: 

when said processor core accesses a specific area, said debug module sequentially transfers address and 
bus control signals from said processor core to the debug tool at predetermined intervals; 

if the access to the specific area is a write access, 6aid debug module sequentially transfers data signals to 

20 the debug tool at predetermined intervals; and 

if the access to the specific area is a read access, said debug module sequentially receives signals from the 
debug tool at predetermined intervals, forms a multi-bit data signal, and sands the data signal to said processor core. 

8. The microprocessor according to claim 7, wherein the predetermined intervals are defined according to the output 
25 clock signal of a dock signal generator. 

9. The microprocessor according to claim 1, wherein said debug module transfers bus interface signals from said 
processor core to the debug tool through a first transfer line bit by bit in series, and the debug tool transfers information 
to said debug module through a second transfer line bit by bit in series. 

10. The microprocessor according to claim 1, wherein: 

said processor core has a mode signal to be enabled when an exception or reset request for starting the 
monitor program is made; and 

said debug module allows said processor core to access the debug tool or a register circuit in said debug 
35 module only when the mode sip/iai is enabled. 

11. The microprocessor according to claim 1, wherein: 

said processor core has a mode signal to be enabled when an exception or reset request for starting the 
monitor program is made; and 

40 said debug module has a control bit that prohibits, when enabled, said processor core from accessing the 

debug tool or a register circuit in said debug module even if the mode signal is enabled. 

12. The microprocessor according to claim 1 , wherein said processor core has: 

a mode that is enabled when an exception or reset request for starting the monitor program is made; 
45 a first write instruction to provide the value of a general register as a data signal and enable a first write signal ; 

and 

a second write instruction to provide the value of the general register as a data signal and enable a second 
write signal. 

do 1 3* The microprocessor according to claim 1 2, wherein: 

said debug module has a control bit for prohibiting said processor core from accessing said debug module; 
a write access to said debug module according to the first write signal is prohibited H the control bit is enabled; 

and 

a write access to said debug module according to the second write signal is enabled without regard to the 
55 control bit- 

14. A microprocessor comprising: 

a processor core for executing a program; and 

a program counter tracer connected to said processor core through an internal debug interface, for providing 
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a program counter signal that reprints the address of an instruction executed by said processor core, the number 
of lines that transmit the program counter 6ignal being smaller than the number of bits of the address. 

1 5. The microprocessor according to claim 1 4, wherein: 
s said processor core asserts an indirect jump signet when executing an indirect jump instruction and provides 

said program counter tracer with the target address of the Indirect jump instruction; and 

upon receiving the asserted indirect jump signal, said program counter tracer accepts the target address, 
transmits the target address as the program counter signal from a lower bit thereof, and provides a program counter 
status signal indicating that the transmission of the target address has started. 

70 

16- the microprocessor according to cleim 14, wherein: 

said processor core asserts an exception signal when an exception occurs and provides said program counter 
tracer with the target address of the exception; and 

upon receiving the asserted exception signal, said program counter tracer accepts the target address, 
75 encodes the target address into information whose number of bib is smaller than that of the target address, transmits 
the coded information as the program counter signal, and provides a program counter status signal indicating that 
the transmission of the target address has started. 

17. The microprocessor according to claim 15, wherein, when said processor core executes a 6econd indirect jump 
20 instruction while said program counter tracer is transmitting the target address of a first Indirect jump instruction; 

said processor core asserts the indirect jump signal when executing the second indirect jump instruction and 
provides said program counter tracer with the target address of the second indirect jump instruction; and 

upon receiving the asserted indirect jump signal, said program counter tracer accepts the target address of 
the second indirect jump instruction, stops transmitting the target address of the first indirect jump instruction, trans- 
25 mils the target address of the second indirect jump instruction as the program counter signal, and provides a program 
counter status signal indicating that the transmission of the target address has started. 

18. The microprocessor according to claim 15, wherein, when an exception occurs while said program counter tracer 
is transmitting the target address of an indirect jump instruction: 

30 said processor core asserts an exception signal indicating that the exception has occurred and provides said 

program counter tracer with the target address of the exception; and 

upon receiving the asserted exception signal, said program counter tracer accepts the target address, sus- 
pends the transmission of the target address of the indirect jump instruction, encodes the target address of the 
exception into information whose number of bits is smaller than that of the target address, transmits the coded 

55 information as the program counter signal, provides a program counter status signal indicating that the transmission 
of the target address of the exception has started, and after the transmission of the coded information is complete, 
resumes the transmission of the target address of the indirect jump instruction. 

19* The microprocessor according to claim 14. wherein: 
40 said processor core asserts a direct jump signal when executing a direct j ump instruction or a taken conditional 

branch instruction and provides said program counter tracer with the target address of the direct jump instruction 
or branch instruction; 

if said program counter tracer is not transmitting the target address of an indirect jump instruction when 
receiving the asserted direct jump signal, said program counter tracer accepts the target address from said processor 
45 core, transmits the target address as the program counter signal from a lower bit thereof, provides a program counter 
status signal Indicating that the transmission of the target address has started; and 

if said program counter tracer is transmitting the target address of an indirect jump instruction when receiving 
the asserted direct jump signal, said program counter tracer only provides a program counter status signal indicating 
that the direct jump instruction or taken conditional branch instruction has been executed, 

6Q 

20. The microprocessor according to claim 14. wherein: 

said processor core asserts a pipeline signal when executing an instruction; 

when the pipeline signal is asserted and is received by said program counter tracer, said program counter 
tracer provides a program counter 6tatus signal indicating that the instruction has been executed by said processor 
ss core; and 

when the pipeline signal is not asserted and is received by said program counter tracer, said program counter 
tracer provides a program counter status signal indicating that the instruction has not been executed. 
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21. The microprocessor accorring to daim 14, wherein, when said processor core executes a second indirect jump 
instruction while said program counter tracer is transmitting the target address of a first indirect jump instruction: 

said processor core asserts an indirect jump signal when executing the second indirect jump Instruction, 
provides said program counter tracer with the target address ol the second indirect jump instruction, and if a proc- 
$ essor core stop signal iG asserted, suspends the execution of the second indirect jump instruction; and 

said program counter tracer asserts the processor core stop signal when the indrect jump signal for the 
second indirect jump instruction is asserted, completes the transmission ol the target address of the first jump 
instruction, accepts the target address of the eecond indirect jump instruction from said processor core, transmits 
the target address of the second indirect jump instruction as the program counter signal, and provides a program 
10 counter status signal indicating that the transmission of the target address has started. 

22. The microprocessor according to claim 14, wherein, when said processor core executes a eecond indirect jump 
instruction while said program counter tracer is transmitting the target address of a first indirect jump instruction: 

said processor core asserts an indirect jump signal when executing the second indirect jump instruction, 

T5 provides said program counter tracer with the target address of the second indirect jump instruction, and If a proc- 
essor core stop signal is asserted, suspends the execution of Ihe second indirect jump instruction; 

said program counter tracer waits for a trace mode signal indicating whether or not the transmission of the 
target address of the first indirect jump instruction must be completed; 

when the trace mode signal indicates to complete the transmission, said program counter tracer asserts the 

so processor core stop signeJ In response to the asserted indirect jump signal for the second indirect jump instruction, 
completes the transmission of the target address of the first indirect jump instruction, accepts the target address of 
the second indirect jump Instruction from said processor core, transmits the target address of the second indirect 
jump instruction as the program counter signal, and provides a program counter status signal indicating that the 
transmission of the target address has started; and 

25 when the trace mode signal indicates not to complete the transmission, said program counter tracer accepts 

the target address of the second indirect jump instruction from said processor core in response to the asserted 
indirect jump signal for the second indirect jump instruction, stops the transmission of the target address of the first 
indirect jump instruction, transmits the target address of the second indirect jump instruction as the program counter 
signal, and provides a program counter status signal Indicating that the transmission of the target address has 

30 started. 

23. The microprocessor according to daim 14, wherein: 

if an interrupt or exception Is externally requested to switch said processor core from a user program to a 
monitor program for debugging a user target system, said processor core suspends the user program, jumps to the 
33 monitor program, and fetches instructions of the monitor program; and 

if said program counter tracer is transmitting the target address of a jump instruction or an exception code 
when said processor core jumps to the monitor program, said processor core delays the fetching of the instructions 
of the monitor program until said program counter tracer completes the transmission. 

40 24. A microprocessor comprising: 

a processor core for executing a program; 

a break circuit for making a break request or asserting a trigger request signal to said processor core when 
an accessed address coincides with a set address, or when an accessed address and data coincide with a set 
address and data; and 

45 a program counter tracer for providing an external status signal indicating that the trigger request signal has 

been asserted after said break circuit asserts the same. 

25. The microprocessor according to claim 24, wherein said program counter tracer encodes the internal state of said 
processor core and provides an external status signal indicating the encoded internal state, 

$0 when said processor core Is In a first internal state and when the trigger request signal is asserted, said 

program counter tracer provides an external status signal indicating an internal state of no trigger request without 
regard to the asserted trigger request signal, and 

when said processor core is in a second internal state and when the trigger request signal is asserted, said 
program counter tracer provides an external status signal indicating that the trigger request has been made. 

55 

26. The microprocessor according to claim 25, wherein the first internal state corresponds to executing a jump instruction 
or producing an exception, and the second internal status corresponds to sequentially executing Instructions or 
causing a pipeline stall. 
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FIG.7 
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FIG.8 



IBAO(INSTRUCTION BREAK ADDRESS Q) REGISTER 




FIG.9 



mCO(INSTRUCTION BREAK CONTROL 0) REGISTER 
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FIG. 11 



DBA0(DATA BREAK ADDRESS 0) REGISTER 
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FIG. 12 

DBCO(DATA BREAK CONTROL 0) REGISTER 




FIG. 13 



DBS(DATA BREAK STATUS) REGISTER 
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FIG. 14 

PBACKPROCESSOR BUS BREAK ADDRESS 0) REGISTER 




FIG. 15 

PBD0(PROCESSOR BUS BREAK DATA 0) REGISTER 
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